128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
ID: b0d0945c-0753-5bc5-b1db-c1b14c8e1f91
STIX ID: report--b0d0945c-0753-5bc5-b1db-c1b14c8e1f91
Feed Name: Microsoft Security
Date Published: 2026-08-04
Date Updated: 2026-08-04
Author: Microsoft Security Research, David Shiran and Ayelet Artzi
Microsoft Defender’s attack disruption autonomously identified and stopped a multi-stage endpoint compromise at QNET where a malicious file executed mshta.exe to fetch a second‑stage payload; the system enforced device isolation 128 seconds after first detection, preventing persistence, lateral movement, and additional payload retrieval and leaving the SOC with a contained incident.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
